R E L A T E D   C O N T E N T
ADVERTISEMENT

Daniel Robinson

Data security is not rocket science

An alarming number of data loss incidents continue to make news, despite the fact that multiple tools exist to address the problem

IT Week, 28 Jan 2008
ADVERTISEMENT

The rash of recent scandals involving loss of records from both government departments and commercial organisations has led many to question just how seriously the security of sensitive data is being taken. One can easily imagine the pressure now being put on various public bodies to tighten up their procedures ­ or else. But the incidents just keep coming and coming. One security web site, attrition.org, even keeps a list of major data exposure incidents, and it is a depressingly long one, at that.

Commentators have often focused blame on those individuals or employees that were handling the data when it was lost, such as the now infamous “junior official” blamed for sending out the UK’s entire child benefit records database on two CDs in an unregistered package last year. How could anyone be so stupid when handling such vital information, you might well ask.

But as IT Week pointed out at the time, these incidents reveal a systematic failure within some organisations to take security seriously and put appropriate measures in place. While it was phenomenally stupid to put sensitive personal information through the post, the question remains as to why a “junior official” was able to get unrestricted access to the entire data set in the first place, and why HM Revenue & Customs had not trained its staff in best practice when handling and processing such information.

With organisations now sensitised to the threat of data loss, there is perhaps a danger that there will be a backlash and that management will insist on a total clampdown on the movement of data and who has access. While this is right and proper in the HMRC case, where the information disclosed may expose millions of people to identity fraud, it would be a sad state of affairs if companies used this as an excuse not to allow employees to work from home, for example.

It’s not as if there aren’t tools on the market to secure data. Seagate’s hard drives with embedded encryption, for example, provide a reasonable level of protection against data on a laptop being exposed if it should be lost or stolen.

You could argue that encryption is still a bit of a black art ­ especially where public key infrastructure (PKI) is concerned ­ and that it is difficult to administer, but in a typical organisation, the number of staff that require such protection is likely to be relatively few.

And then there are tools that enable firms to enforce policy on removable storage, so that only authorised staff can copy files to USB Flash drives and the like. These products have been around for several years now, and are built into nearly every management suite of any significance, so why are they not used more widely by companies that could genuinely benefit from the technology?

This is only a guess, but I imagine that IT is often rather low on the list of priorities for departments like the HMRC, and proper security may have been seen as an expense they couldn’t afford. Sadly, as events such as the child benefit case and the more recent theft of a laptop stolen from the Ministry of Defence illustrate, harsh reality has a habit of proving otherwise.

Tags: Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
RELATED ARTICLES
M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities